Reachable assertion in libheif - CVE-2026-62377
Published: June 29, 2026 / Updated: August 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to reachable assertion in HeifContext::get_track() when processing a crafted HEIF sequence file that is accepted with no registered sequence tracks. A remote attacker can trick the victim into opening a crafted file to cause a denial of service.
User interaction is required to open or process the crafted HEIF file. In builds with assertions disabled, the issue may instead lead to undefined behavior due to dereferencing an empty track map.
Affected software
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Fedora
Desktop Applications Module
SUSE Package Hub 15
libheif1-debuginfo
libheif-ffmpeg
gdk-pixbuf-loader-libheif
libheif-devel
libheif-ffmpeg-debuginfo
gdk-pixbuf-loader-libheif-debuginfo
libheif-dav1d-debuginfo
libheif1
libheif-aom
libheif-jpeg
libheif-jpeg-debuginfo
libheif-aom-debuginfo
libheif-rav1e
libheif-dav1d
libheif-rav1e-debuginfo
libheif-debugsource
libheif
aom
How to mitigate CVE-2026-62377
libheif1-debuginfo - update to 1.23.1-150700.3.18.1
libheif-ffmpeg - update to 1.23.1-150700.3.18.1
gdk-pixbuf-loader-libheif - update to 1.23.1-150700.3.18.1
libheif-devel - update to 1.23.1-150700.3.18.1
libheif-ffmpeg-debuginfo - update to 1.23.1-150700.3.18.1
gdk-pixbuf-loader-libheif-debuginfo - update to 1.23.1-150700.3.18.1
libheif-dav1d-debuginfo - update to 1.23.1-150700.3.18.1
libheif1 - update to 1.23.1-150700.3.18.1
libheif-aom - update to 1.23.1-150700.3.18.1
libheif-jpeg - update to 1.23.1-150700.3.18.1
libheif-jpeg-debuginfo - update to 1.23.1-150700.3.18.1
libheif-aom-debuginfo - update to 1.23.1-150700.3.18.1
libheif-rav1e - update to 1.23.1-150700.3.18.1
libheif-dav1d - update to 1.23.1-150700.3.18.1
libheif-rav1e-debuginfo - update to 1.23.1-150700.3.18.1
libheif-debugsource - update to 1.23.1-150700.3.18.1
libheif - addressed in versions 1.23.5-3.el10_3, 1.23.5-3.el10_4
aom - addressed in versions 3.13.3-1.el10_3, 3.13.3-1.el10_4